fix(security): workflow permissions and two e2e regexes - #43
Merged
Merged
Conversation
Closes #26. **Both workflows without a `permissions` block now read and nothing else.** `ci.yml` only typechecks and `publisher-image.yml` pushes to Docker Hub with its own credentials, so neither needs the GitHub token to write anything, and without the block it gets the repository's default. `release.yml`, `pages.yml` and `dev-sync.yml` already declared theirs. **The e2e fake publishers compare the header whole.** Both parsed it with `/^Bearer\s+(.+)$/`, the same quadratic shape the real publisher just lost. In a test the exact header GoodBit sends is the thing being checked, so an equality says more than a parse did. The em dashes in the two workflow comments go too. `compress.spec.ts` and `publishGoodBits.spec.ts`: 10 passed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #26. Code scanning alerts 1, 2, 6, 16.
ci.ymlandpublisher-image.ymlgetpermissions: contents: read. Neither needs the token to write (the image goes to Docker Hub with its own credentials; the gha layer cache uses the runner's token). The other three workflows already declared theirs./^Bearer\s+(.+)$/; now an exact equality with the header GoodBit sends, which is what the test is checking anyway.Gate:
compress.spec.ts+publishGoodBits.spec.ts, 10 passed; typecheck green.🤖 Generated with Claude Code